Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-40357 |
|
Unsafe Deserialization in deserialization (CVE-2026-40357)
vulnerability in deserialization (CVE-2026-40357). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35439 |
|
Unsafe Deserialization in deserialization (CVE-2026-35439)
vulnerability in deserialization (CVE-2026-35439). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40367 |
|
Vulnerability in microsoft (CVE-2026-40367)
vulnerability in microsoft (CVE-2026-40367). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40360 |
|
Out-of-Bounds Read in microsoft (CVE-2026-40360)
vulnerability in microsoft (CVE-2026-40360). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35436 |
|
Vulnerability in microsoft (CVE-2026-35436)
vulnerability in microsoft (CVE-2026-35436). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40361 |
|
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
|
| CVE-2026-40358 |
|
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
|
| CVE-2026-40359 |
|
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
|
| CVE-2026-40364 |
|
Vulnerability in microsoft (CVE-2026-40364)
vulnerability in microsoft (CVE-2026-40364). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40363 |
|
Vulnerability in microsoft (CVE-2026-40363)
vulnerability in microsoft (CVE-2026-40363). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40362 |
|
Vulnerability in microsoft (CVE-2026-40362)
vulnerability in microsoft (CVE-2026-40362). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34637 |
|
Out-of-Bounds Write in adobe (CVE-2026-34637)
out-of-bounds write in adobe (CVE-2026-34637). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34638 |
|
Use-After-Free in adobe (CVE-2026-34638)
vulnerability in adobe (CVE-2026-34638). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34661 |
|
Out-of-Bounds Write in adobe (CVE-2026-34661)
out-of-bounds write in adobe (CVE-2026-34661). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34636 |
|
Out-of-Bounds Write in adobe (CVE-2026-34636)
out-of-bounds write in adobe (CVE-2026-34636). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33110 |
|
Unsafe Deserialization in deserialization (CVE-2026-33110)
vulnerability in deserialization (CVE-2026-33110). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33112 |
|
Unsafe Deserialization in deserialization (CVE-2026-33112)
vulnerability in deserialization (CVE-2026-33112). Successful exploitation can lead to full system takeover.
|
| CVE-2025-53844 |
|
Out-of-Bounds Write in fortinet (CVE-2025-53844)
out-of-bounds write in fortinet (CVE-2025-53844). Successful exploitation can lead to full system takeover.
|
| CVE-2025-43524 |
|
Vulnerability in apple (CVE-2025-43524)
vulnerability in apple (CVE-2025-43524). Successful exploitation can lead to full system takeover.
|
| CVE-2025-46311 |
|
Vulnerability in apple (CVE-2025-46311)
vulnerability in apple (CVE-2025-46311). Confidential information can be exposed externally.
|
| CVE-2026-42899 |
|
Vulnerability in dotnet (CVE-2026-42899)
vulnerability in dotnet (CVE-2026-42899). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.27, 9.0.16, 10.0.8` or later.
|
| CVE-2026-35433 |
|
Vulnerability in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-35433)
vulnerability in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-35433). Confidential information can be exposed externally. Mitigation: upgrade to `10.0.8` or later.
|
| CVE-2026-32177 |
|
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
|
| CVE-2026-43513 |
|
Vulnerability in tomcat (CVE-2026-43513)
vulnerability in tomcat (CVE-2026-43513). Confidential information can be exposed externally. Mitigation: upgrade to `10.1.55, 11.0.22, 9.0.118` or later.
|
| CVE-2026-42498 |
|
Information Disclosure in tomcat (CVE-2026-42498)
vulnerability in tomcat (CVE-2026-42498). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.1.55, 11.0.22, 9.0.118` or later.
|
| CVE-2026-41284 |
|
Vulnerability in tomcat (CVE-2026-41284)
vulnerability in tomcat (CVE-2026-41284). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.1.55, 11.0.22, 9.0.118` or later.
|
| CVE-2023-27753 |
|
Unrestricted File Upload in CVE-2023-27753 (CVE-2023-27753)
vulnerability in CVE-2023-27753 (CVE-2023-27753). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7432 |
|
Vulnerability in ivanti (CVE-2026-7432)
vulnerability in ivanti (CVE-2026-7432). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8051 |
|
OS Command Injection in ivanti (CVE-2026-8051)
OS command injection in ivanti (CVE-2026-8051). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8390 |
|
Use-After-Free in mozilla (CVE-2026-8390)
vulnerability in mozilla (CVE-2026-8390). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8389 |
|
Buffer Overflow in mozilla (CVE-2026-8389)
vulnerability in mozilla (CVE-2026-8389). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43884 |
|
SSRF (Server-Side Request Forgery) in wwbn/avideo (CVE-2026-43884)
SSRF in wwbn/avideo (CVE-2026-43884). Confidential information can be exposed externally. Exploitable via `POST /plugin/AI/receiveAsync.json.php`.
|
| CVE-2026-43873 |
|
Vulnerability in wwbn/avideo (CVE-2026-43873)
vulnerability in wwbn/avideo (CVE-2026-43873). Confidential information can be exposed externally. Exploitable via ``cloneSiteURL``.
|
| CVE-2026-43655 |
|
Out-of-Bounds Read in apple (CVE-2026-43655)
vulnerability in apple (CVE-2026-43655). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43652 |
|
Vulnerability in apple (CVE-2026-43652)
vulnerability in apple (CVE-2026-43652). Confidential information can be exposed externally.
|
| CVE-2026-43658 |
|
Buffer Overflow in apple (CVE-2026-43658)
vulnerability in apple (CVE-2026-43658). Confidential information can be exposed externally.
|
| CVE-2026-39870 |
|
Buffer Overflow in apple (CVE-2026-39870)
vulnerability in apple (CVE-2026-39870). Confidential information can be exposed externally.
|
| CVE-2026-43656 |
|
Out-of-Bounds Write in apple (CVE-2026-43656)
out-of-bounds write in apple (CVE-2026-43656). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43660 |
|
Vulnerability in apple (CVE-2026-43660)
vulnerability in apple (CVE-2026-43660). Confidential information can be exposed externally.
|
| CVE-2026-43668 |
|
Use-After-Free in apple (CVE-2026-43668)
vulnerability in apple (CVE-2026-43668). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43654 |
|
Vulnerability in apple (CVE-2026-43654)
vulnerability in apple (CVE-2026-43654). Confidential information can be exposed externally.
|
| CVE-2026-43661 |
|
Vulnerability in apple (CVE-2026-43661)
vulnerability in apple (CVE-2026-43661). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39871 |
|
Vulnerability in apple (CVE-2026-39871)
vulnerability in apple (CVE-2026-39871). Confidential information can be exposed externally.
|
| CVE-2026-28951 |
|
Authorization Flaw in apple (CVE-2026-28951)
vulnerability in apple (CVE-2026-28951). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28959 |
|
Vulnerability in apple (CVE-2026-28959)
vulnerability in apple (CVE-2026-28959). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28976 |
|
Information Disclosure in apple (CVE-2026-28976)
vulnerability in apple (CVE-2026-28976). Confidential information can be exposed externally.
|
| CVE-2026-28955 |
|
Buffer Overflow in apple (CVE-2026-28955)
vulnerability in apple (CVE-2026-28955). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28995 |
|
Privilege Escalation in apple (CVE-2026-28995)
vulnerability in apple (CVE-2026-28995). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28965 |
|
Vulnerability in apple (CVE-2026-28965)
vulnerability in apple (CVE-2026-28965). Confidential information can be exposed externally.
|
| CVE-2026-28964 |
|
Vulnerability in apple (CVE-2026-28964)
vulnerability in apple (CVE-2026-28964). Confidential information can be exposed externally.
|